Microsoft Defender External Attack Surface Management (EASM) for Splunk provides full visibility into an organization’s externally exposed digital footprint using the Microsoft Defender EASM REST APIs.
This Splunk App enables security teams to discover, monitor, analyze, and operationalize external attack surface data directly in Splunk—without relying on the Microsoft Defender External Attack Surface Management (EASM) portal User Interface.
Microsoft Defender EASM discovers and tracks the following asset classes:
- Domains
- Hosts
- Pages
- IP Addresses
- IP Blocks
- Autonomous System Numbers (ASNs)
- SSL Certificates
- WHOIS Contacts
- DNS Records
| Feature | Description |
|---|---|
| 🌐 Asset Discovery | Continuous discovery of internet-facing assets |
| 🧭 Asset Inventory | Unified inventory across all asset types |
| 🔎 Exposure Visibility | Identify exposed infrastructure and services |
| 🧩 Attribution Context | Asset ownership and relationship mapping |
| 🕵️ Change Tracking | Detect newly discovered or modified assets |
| 🧾 Evidence Preservation | Raw API data retained for auditability |
| Feature | Description |
|---|---|
| 📊 Asset Growth Trends | Track attack surface expansion over time |
| 🔄 Asset Lifecycle | New, existing, and removed asset tracking |
| 🧱 Infrastructure Mapping | Domain → host → IP → ASN relationships |
| 🔐 Certificate Monitoring | SSL certificate inventory and expiration |
| 🧠 Contextual Pivoting | Pivot across assets, ownership, and evidence |
| Feature | Description |
|---|---|
| 📡 Modular Input Framework | Secure API-based ingestion |
| 🔑 Credential Management | Encrypted credential storage via Splunk |
| 🌐 Proxy Support | Enterprise proxy compatibility |
| 🩺 Health Monitoring | API reachability and ingestion status |
| 📋 Operational Logging | Full ingestion traceability |
| ⏱️ Rate-Limit Awareness | Safe polling and throttling handling |
| Dashboard | Description |
|---|---|
| 🧭 Overview | High-level external exposure summary |
| 🌐 Attack Surface Summary | Aggregated exposure and findings summary |
| 🛡️ Security Posture | Posture scoring and posture-related insights |
| 📜 GDPR Compliance | GDPR-oriented insights derived from exposure data |
| 🔟 OWASP Top 10 | OWASP Top 10 insights derived from exposure data |
| 🧩 CWE Top 25 | CWE Top 25 insights derived from exposure data |
| 🚨 CISA Known Exploits | KEV-oriented insights derived from exposure data |
| 📈 Trends | Inventory and activity trends |
| ⚙️ Operations | Ingestion and operational visibility |
| ❤️ Health | API and data freshness monitoring |
| 🗂️ Inventory | Unified inventory across asset types |
| 🖥️ Assets | Asset resource listing and pivoting |
| 👥 Users | User account inventory and exposure visibility |
| 📜 Activity Logging | Audit trail and user activity visibility |
| 🔄 Inventory Changes | Add/remove tracking (if ingested) |
| 🔍 Discovery | Discovery templates and run visibility |
| 🔌 Data Connections | Data connection inventory |
| ✅ Data Connection Validation | Data connection validation visibility |
| 🧰 Task Manager | Task orchestration visibility |
| 📋 Tasks | Task detail listing |
| 📊 Reports | Report inventory |
|
| Operation group | Operation Type | Description |
|---|---|---|
| Assets | Data plane | Retrieve or update assets by assetID or designated search parameters. |
| Data Connections | Data plane | Retrieve, create, validate or delete a data connection. |
| Discovery groups | Data plane | Retrieve, create, run or remove discovery groups, and retrieve discovery results. |
| Discovery templates | Data plane | Retrieve discovery templates. |
| Reports | Data plane | Retrieve a recent snapshot of asset summary values, or historic summary details. |
| Saved filters | Data plane | Retrieve a list of saved filters, or retrieve, create or remove a specific filter. |
| Tasks | Data plane | Retrieve a list of tasks, or retrieve, cancel or download data for a specific taskID. |
| Labels | Control plane | Retrieve labels, or create, update, or delete a label. |
| Operations | Control plane | Retrieve a list of operations. |
| Workspaces | Control plane | Retrieve a list of workspaces by resource group or subscription, or create, update, or delete a specific workspace. |
| Tasks | Control plane | Retrieve tasks submitted in the given workspace. |
The app ingests raw JSON events using the following sourcetypes (as configured in default/inputs.conf):
defender:easm:domaindefender:easm:hostdefender:easm:pagedefender:easm:ip_addressdefender:easm:ip_blockdefender:easm:asndefender:easm:ssl_certificatedefender:easm:whois_contactdefender:easm:dns_record
defender:easm:exposure_insight
defender:easm:discovery_templatedefender:easm:discovery_rundefender:easm:task
defender:easm:data_connectiondefender:easm:data_connection_validation
defender:easm:reportdefender:easm:report_output
defender:easm:rbac:role_definitiondefender:easm:rbac:role_assignmentdefender:easm:workspacedefender:easm:operationsdefender:easm:license
Navigation matches default/data/ui/nav/default.xml:
- Overview
- Attack Surface Summary
- Security Posture
- GDPR Compliance
- OWASP Top 10
- CWE Top 25
- CISA Known Exploits
- Trends
- Operations
- Health
- Inventory
- Assets
- Inventory Changes
- Discovery
- Labels
- Billable Assets
- Data Connections
- Data Connection Validation
- Task Manager
- Tasks
- Reports
- User Permissions
- User Activity
- Privileged Role Activity
- Workspaces
- Role Definitions
- Policies
- Support & Troubleshooting
- Download
Microsoft_Defender_EASM_For_Splunk_App-1.0.0.tar.gz - In Splunk Web, go to Apps → Manage Apps
- Select Install app from file
- Upload the package
- Restart Splunk if prompted
This app uses a guided setup workflow (setup.xml) to ensure secure and AppInspect-compliant configuration.
Navigate to Apps → Microsoft Defender EASM → Setup to configure:
- Microsoft Defender EASM API credentials (stored securely)
- Optional enterprise proxy settings
- Modular input enablement and polling intervals
All inputs are disabled by default and must be enabled through the setup interface.
- Defender EASM API Key
- API Base URL
https://api.defender.microsoft.com - Request Timeout
- Verify SSL Certificates
- Enable Proxy
- Proxy URL
- Proxy Username
- Proxy Password
- Domains
- Hosts
- Pages
- IP Addresses
- IP Blocks
- ASNs
- SSL Certificates
- WHOIS Contacts
- DNS Records
- Test API connectivity
- Validate authentication
- Verify permissions
- Automatic validation on first launch
Run the following search in Splunk:
index=security_defender_easm sourcetype=defender:easm:*
| stats count by sourcetype
- Splunk Enterprise or Splunk Cloud
- Python 3.x (Splunk bundled)
- Microsoft Defender EASM API Access
- Network access to Defender EASM APIs
- Proper Splunk directory structure
- No hardcoded credentials
- Inputs disabled by default
- Encrypted credential storage
- app.manifest included
- MIT License
- Setup-based configuration
- Verify API key permissions
- Test API connectivity
- Confirm inputs are enabled
- Check Splunk internal logs
- Validate authentication scope
- Check rate limits
- Confirm Defender EASM service availability
- Validate proxy URL and credentials
- Confirm SSL inspection compatibility
- Test proxy connectivity from Splunk
-
Defender EASM REST API
https://learn.microsoft.com/en-us/rest/api/defenderforeasm/ -
Azure Python SDK (Preview)
https://learn.microsoft.com/en-us/python/api/overview/azure/defender-easm-readme -
Splunk Documentation
https://docs.splunk.com
MIT License 2.0